#!/bin/bash
#

## Firewall Script
#  01-07-26  by Erik Wegner
#  ftp-forward <InternalInterface> <ExternalInterface>
#

INT=$1  # InternalInterface
EXT=$2  # ExternalInterface

if test -z $1 || test -z $2 ; then
	echo "ftp-forward <InternalInterface> <ExternalInterface>"
	echo "e.g.: ftp-forward eth0 ppp0"
	exit 2
fi

# Pfad zu IPTables
if test -z $IPTABLES ; then
	IPTABLES=/usr/sbin/iptables
fi

## Ports
#  Nicht-privilegierte = 1024-65535
P_HIGH=1024:65535
P_FTP=21

echo -e "\n# FTP-Forward (control connectio) $INT[$P_HIGH] -> $EXT[$P_FTP]"
echo "$IPTABLES -A FORWARD -o $EXT -i $INT -m state --state NEW \\"
echo "	-p TCP --sport $P_HIGH --dport $P_FTP \\"
echo "	-j ACCEPT"
echo -e "\n# FTP-Forward (passive data) $INT[$P_HIGH] -> $EXT[$P_HIGH]"
echo "$IPTABLES -A FORWARD -o $EXT -i $INT -m state --state NEW \\"
echo "	-p TCP --sport $P_HIGH --dport $P_HIGH \\"
echo "	-j ACCEPT"

